2 Remove Virus

Russian spies exploit vulnerable IP cameras across Europe to track military shipments

Russian state-backed hackers are systematically compromising internet-connected security cameras across Europe to monitor military logistics and weapons deliveries destined for Ukraine, according to a joint warning from the Dutch General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD). The agencies said the campaign targets exposed IP cameras in NATO countries and Ukraine to gather intelligence on troop movements, military equipment, and supply routes.

 

 

The Dutch intelligence services said the attackers scan the internet for vulnerable cameras before exploiting weak passwords, outdated firmware, and insecure default configurations. Once access is obtained, the hackers use automated image recognition technology to analyze live video feeds and identify military vehicles, equipment, and cargo moving through strategic transport corridors.

According to internet intelligence company Censys, more than one million IP cameras are currently exposed online worldwide. Researchers identified approximately 87,000 vulnerable cameras across Europe, including around 4,000 located in Ukrainian cities. Dutch officials said only a limited number of compromised cameras were found along military logistics routes in the Netherlands, and organizations operating those devices have been notified.

The intelligence agencies warned that the campaign demonstrates how poorly secured internet-connected devices can become valuable espionage tools. Beyond collecting video footage, access to surveillance systems can help attackers understand security procedures, identify infrastructure, and monitor the movement of military assets without needing to deploy personnel on the ground.

Authorities urged organizations and individuals operating internet-connected cameras to change default passwords, enable multi-factor authentication where available, install the latest firmware updates, and avoid exposing surveillance devices directly to the public internet. They also recommended limiting remote access to trusted networks to reduce the risk of compromise.

The warning comes amid continued cyber espionage activity linked to Russian intelligence services. Earlier this week, cybersecurity agencies from the United States and allied nations warned that Russian state-sponsored hackers are also targeting internet-facing routers used by governments, critical infrastructure operators, and defense organizations to establish long-term access to sensitive networks.